A Requires Improvement rating records what CQC could evidence on the day they looked. For one or more regulations, the evidence was not there. The route back to Good runs through the regulation that was breached.
That decides what you do on Monday. Read it as a reputational problem and you write a plan full of intentions. Read it as a breach finding and you rebuild the evidence trail. This article covers why Safe accounts for most RI ratings, what a credible action plan looks like, how to sequence the first 90 days, and where the coming framework change leaves you.
Start with the regulation
Your report has two layers. The narrative under each quality statement is what patients and your PPG read. Underneath it is the breach: a named regulation, and the specific evidence CQC could not find. Trace every RI domain back to its regulation before you plan anything, because re-assessment tests the breach.
The Single Assessment Framework is still in force: five key questions, 34 quality statements, with evidence gathered against those statements over time. Your report therefore tells you which evidence category came up short. Read it literally.
Why it is nearly always Safe
Safe maps to Regulation 12, safe care and treatment. It has the most key lines of enquiry and the most recorded breaches in general practice. Practice Index, in their commentary on the sector, hold that Safe connects to effectively every GP service ever rated Requires Improvement or Inadequate. CQC publish no figure to that effect, so treat it as commentary, though it matches what most practice managers see.
The reason is structural. Safe is where the evidence is documentary and binary: either the safety alert was actioned and minuted, or there is no record of it. That makes it the easiest domain to fail and the most tractable one to fix.
The problems recur consistently enough to use as a checklist:
- safeguarding, emergency and IPC training gaps across clinical and non-clinical staff
- missing DBS checks and incomplete recruitment verification
- staff immunisation status not evidenced
- fire, health and safety risk assessments with actions never closed out
- recommended emergency medicines not stocked
- significant events recorded but never disseminated, and SEAs that omit the likelihood of recurrence
- safety alerts not managed, actioned or discussed at a minuted meeting
- blank prescriptions not logged and tracked at branch sites
- no process for monitoring non-medical prescriber competency
- reception staff unfamiliar with triage protocols that exist and are perfectly good
- gaps in high-risk medicines monitoring: incomplete searches, and review discussions never documented
- an outdated practice website
Most of that list describes evidence failure. The practice does the thing. It cannot prove it does the thing.
The medicines cluster inside Safe
Safe contains a tight cluster that appears in RI reports more than anything else: high-risk drug monitoring, medication reviews, safety alerts, and prescribing safety searches. It has the most direct patient-harm potential, and it takes real clinical hours to close. The medicines breaches behind a Requires Improvement rating sets out what the evidence must look like.
CQC runs a suite of clinical searches, developed with Ardens, at GP assessments: safe prescribing, high-risk drug monitoring, long-term condition management, and identification of potential missed diagnoses. High-risk drugs in scope include ACE inhibitors and ARBs, amiodarone, DOACs, lithium, and the DMARDs: azathioprine, leflunomide and methotrexate. The intervals have deliberate tolerance built in, because CQC’s target is the patient who has dropped out of the system.
You will not know what an assessor finds until you run those searches yourself. CQC clinical searches: what they look for and how to work the output covers the mechanics, and our CQC searches and preparation service exists because working the output is where practices run out of hours. A real backlog usually has a systemic cause, a pattern set out in high-risk drug monitoring in primary care.
What a credible action plan looks like
Action plans fail for predictable reasons. They restate the breach as an aspiration: “we will improve monitoring of patients on high-risk medicines”. They name no owner beyond “the practice”, and every date is “ongoing”.
A credible plan is boring and specific. It names the regulation, the breach, the person responsible, the date, and the evidence artefact that will exist at the end. That last one is the part practices skip. Compare “review our safety alert process” with a line an outsider could check: “MHRA alerts triaged by [name] within the agreed interval, recorded on the alert log, standing item at the monthly clinical meeting, minutes as evidence.” The interval is yours to set and justify clinically; the example is about the shape of the line.
Good plans also separate backlog from system. Clearing 300 overdue methotrexate reviews is a backlog task with an end date. Making sure a 301st never accumulates is a system task with an owner and a recurring interval. Plans that do only the first are back where they started within a year.
Sequencing the first 90 days
Order matters, because the cheap wins buy room for the expensive ones.
- Days 1–14, establish ground truth. Map every breach to its regulation, then run the searches and size the actual backlog. A plan built on an assumed backlog is wrong from the first line.
- Days 1–30, close the administrative breaches. Training records, DBS files, emergency medicines stock, risk assessment actions, the website. They need attention more than clinical capacity, and an assessor checks them fastest.
- Days 15–60, clinical backlog and the systems around it. Recall the patients the searches surfaced and complete the reviews. Document each discussion at the time, because a review nobody wrote up did not happen. In parallel, stand up the recurring processes such as alert triage and prescriber competency monitoring, so the backlog cannot re-form.
- Days 60–90, prove it. Re-run the searches against your day-14 baseline and audit a sample of the documentation. Evidence of improvement has to have existed long enough to show a trend.
Where external clinical capacity fits
Much of an RI action plan is beyond any external clinical service. Fire risk assessments, DBS files, staff immunisation records, premises and your website are yours. What a clinical service can take on is the medicines and clinical-monitoring cluster and the documentation trail underneath it, the part with a real clinical hour cost.
Virtual Pharmacist delivers award-winning, fully managed clinical pharmacy services to GP practices, PCNs and ICBs, with 375+ UK partnerships and 88+ PCNs served. That includes CQC searches and preparation, high-risk drug monitoring, clinical and structured medication reviews, and discharge reconciliation. Delivery is remote and sessional, under Virtual Pharmacist’s own clinical governance, aligned to your practice’s agreed workflow and monitored through clinical activity KPIs. Every pharmacist is verified on the GPhC register before engagement, and we hold the NHS Data Security and Protection Toolkit, DCB0129 clinical safety compliance, ICO registration and Cyber Essentials.
Nobody can tell you what your next rating will be, and we will not try. A managed service can take the medicines cluster off your critical path. If it would help to talk the report through, our pharmacists have sat with practices at every stage, from the week the draft report lands to the re-assessment.
One note on timing
If you are sitting on an RI rating now, the framework is moving underneath you. CQC is replacing the SAF with four sector-specific frameworks, and GP practices fall under the new primary care framework, alongside dental, community health, urgent care and independent clinics. The consultation closed on 12 June 2026, final frameworks are due this summer, and implementation begins at the end of 2026 and runs to 2028. The useful part is the new rating characteristics: plain-English descriptors of what Good, Requires Improvement and Outstanding look like under each key question, replacing a point-based scoring model providers found hard to interpret.
None of that argues for waiting. Regulation 12 is legislation and the transition does not touch it, so the work you do now carries over. CQC is aiming to deliver 9,000 assessments by the end of September 2026, against 4,308 by the end of 2025, and that step up lands well before the new frameworks do.
Frequently asked questions
Which domain is usually behind a Requires Improvement rating?
Usually Safe. It maps to Regulation 12, safe care and treatment, and has the most key lines of enquiry and the most recorded breaches in general practice.
Will improving our patient survey scores move an RI rating?
No. Re-assessment tests the specific breach named in your report, so survey scores will leave an RI on a Regulation 12 medicines breach exactly where it is.
Do the CQC clinical searches penalise us for bloods that are slightly overdue?
There is deliberate tolerance built into the monitoring intervals. CQC’s target is the patient who has dropped out of the system altogether.
Is it worth starting now when the assessment framework is about to change?
Yes. Regulation 12 is legislation, and the move to the new primary care framework does not touch it, so the work carries over intact.
How much of an action plan can an external clinical pharmacy service take on?
Part of it. Fire risk assessments, DBS files, premises and your website stay with the practice. A remote clinical service can take on the medicines and clinical-monitoring cluster and the documentation trail underneath it.
If the medicines section of your action plan is written in the future tense, with no owner and no date, that is the section that will not survive re-assessment. Contact Virtual Pharmacist to discuss what your practice needs and how a remote, managed service could fit.